Skip to main content

Compliance

The Compliance page maps scan results onto security frameworks and benchmarks. Each framework card shows a 0-100 score with its pass, fail, and manual counts.

The frameworks​

The page lists the frameworks the selected scan produced, so the cards on it can differ between one scan and another. The ones seen most often:

FrameworkFreePro
CIS AWS Foundations Benchmark✓✓
AWS Foundational Security Best Practices✓✓
NIST 800-53✓✓
PCI DSS✓✓
SOC 2✓✓
ISO/IEC 27001✓✓
HIPAA✓✓

Every framework is included on every plan, Free as well as Pro. What a plan changes is how many accounts are scanned and how often.

Compliance is scan-scoped​

Posture is always read against one completed scan. By default the page reads the latest completed scan. Once more than one exists, a scan selector in the header reads posture against any completed run, which is useful for reading posture as it stood before a release.

Drill into a framework​

Click a card to see every requirement with its status. Expand a requirement for its evidence and its control text. The evidence lists the findings behind the control grouped per check, with Failing, Passing, and All tabs (failing first whenever anything fails) and a pass meter showing how many resources pass. Each listed finding carries its resource, account, region, severity, and status. The control's description, rationale, and remediation follow below.

Click any finding to open its full detail in place of the framework view, the same page the Findings view uses. Its breadcrumb names the framework and the requirement; tap it (or press Escape) to return to the requirement where you left off.

Controls that cannot be verified automatically are marked Manual: they count toward the requirement list but need human attestation.

Reports​

Each framework offers Download report. Reports are generated on demand, so the first download can take a moment. Per-scan full-result archives are also available from the Scans page.

Reading the score​

The score is the share of the framework's requirements that passed in the selected scan. Manual requirements count as not met, as an auditor would read them, so a framework with many manual requirements keeps a lower score until they are reviewed outside Argus. Two practical consequences:

  • Muted findings are suppressed from active posture, so accepted risks stop dragging a framework down, with the reason on record. See Mute rules.
  • The score moves only when a new scan completes. Remediation shows up after the next run, not the moment the fix lands on the resource.